A reference architecture is a shared map of the parts of a cloud service and who operates each one. The CCSP exam uses it to test whether you can tell what the customer controls in each service model, because that decides which security controls the customer must build and which it can only request or verify.
Infrastructure as a Service (IaaS) gives the customer virtual machines, virtual networks and storage. The provider runs the physical data center, hardware and hypervisor; the customer installs and patches the guest operating system, middleware and applications, and configures firewalls and identity. Platform as a Service (PaaS) moves the operating system and runtime to the provider: you deploy code or use a managed database, and the provider patches the platform underneath. Software as a Service (SaaS) delivers a finished application; the customer mainly controls its users, their permissions, configuration settings and the data it puts in.
ISO/IEC 17788 describes the same idea as cloud capability types. An infrastructure capability type lets the customer provision and use processing, storage or networking. A platform capability type lets the customer deploy and run applications written in languages and tools the provider supports. An application capability type lets the customer use the provider's applications. Named service categories such as compute as a service, data storage as a service, network as a service and communications as a service fit inside these types.
The pattern to remember is that as you move from IaaS to PaaS to SaaS, the customer gives up control and gains convenience. Less control means you rely more on contracts, service level agreements and third-party assurance reports to confirm the provider's controls. Some responsibilities never move: in every model the customer owns its data, decides who gets access, and is accountable to regulators and customers if that data is mishandled.
Key terms
- IaaS
- A service model in which the customer rents virtual compute, storage and networking and manages everything from the guest operating system up.
- PaaS
- A service model in which the provider runs the operating system and runtime, and the customer deploys and manages its own applications and data.
- SaaS
- A service model in which the provider delivers a complete application, and the customer manages users, configuration and data.
- Cloud capability type
- ISO/IEC 17788's classification of what a service offers the customer: infrastructure, platform or application capability.
A startup runs its web app on managed PaaS, keeps files in object storage and uses a SaaS email suite. When a critical kernel flaw is announced, the startup does nothing for the PaaS and SaaS parts because the providers patch those, but it must still patch the two IaaS virtual machines it runs for a legacy reporting tool.
Check yourself
In PaaS, who is responsible for patching the runtime and operating system?
The provider; the customer is responsible for its application code, configuration and data.
Which service model gives the customer the most control and therefore the most security responsibility?
IaaS, because the customer manages the guest operating system and everything above it.
What does the application capability type describe?
A service where the customer uses the provider's applications, which corresponds to SaaS.